Security Checks Simplified: How to Implement Best Practices with Ease

QCon London 2023

Session security

Security Checks Simplified: How to Implement Best Practices with Ease

Monday Mar 27 / 10:35AM BST, Windsor (5th Fl.)

Abstract

Many organizations are confronted with multiple issues flagged by security tools; are you struggling with security remediation? If so, this talk is for you.   

We will discuss the OpenSSF Scorecard, a tool that tells us how well a code repository follows essential security best practices related to code vulnerabilities, maintenance, continuous testing, and minimising source and build risk. We will discuss what the tool measures, why it is necessary, and the steps involved in getting a good score.  

We will then discuss how automation and tooling can streamline and simplify the process of applying these best practices. We will introduce an open-source project, Secure-Repo, that aims to automate security remediation tasks. This tool can help developers address security issues flagged by OpenSSF Scorecard.  

At the end of this talk, you will better understand how to apply best practices to improve the security of your code repository using automation and tooling.

Topics

security repository best practices security remediation automation tooling open source
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon London 2023 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Monday 27 March

10:35 Windsor (5th Fl.) Session security Security Checks Simplified: How to Implement Best Practices with Ease Varun Sharma CEO and Co-Founder @Step_Security 11:50 Mountbatten (6th Fl.) Session cloud How to Build a Successful Cloud Capability on a Heavy Regulated Organization Ana Sirvent Principal DevOps Engineer @KPMG UK 13:40 Windsor (5th Fl.) Session security Sustainable Security Requirements with the ASVS Josh Grossman Application Security Consultant & CTO @BounceSecurity 14:55 Rutherford (4th Fl.) Unconference Unconference: Building Security in Earlier Shane Hastie Global Delivery Lead @SoftEd, Lead Editor for Culture & Methods @InfoQ 16:10 Westminster (4th Fl.) Panel Panel: Building Security in Earlier Ana Sirvent, Josh Grossman, Varun Sharma, Henry Tze 17:25 Whittle (3rd Fl.) Session automation Getting Developers into F1 Driver Seats with Security? Henry Tze Lead Cloud Security Engineer @Virgin Media O2